Tuesday, November 1, 2022

Lessons Learned: Flashback to Summer’s Great Rogers Outage (Part 2)

In our last post, we looked at the Great Rogers Outage of 2022.

Millions of Canadians experienced life without mobile and Internet service – a necessity in our pandemic life. The cause was traced back to a system-change gone wrong. It appears that though Rogers had tested some parts of the planned change, it was insufficient to identify all the issues. The result was that the network got flooded with traffic and then the systems went down.

 

What are some lessons we can learn from this outage?

Major Controls Frameworks, like COBIT and ISO27001, and audit standards, like SOC2, require that management implement change management controls. Consequently, the outage presents a unique opportunity to understand what can go wrong when it comes to change management. Moreover, it highlights what types of controls are relevant from a real-live scenario - as Rogers documented in its submission to the CRTC. 


With that in mind, let’s look at four lessons from the Great Rogers Outage of 2022. 


Lesson #1: The Importance of Redundancy

When commenting on the impact of the outage on governments within Canada, Rogers noted: “It is important to note that in most of the cases, we provide a portion of the telecommunications solution, but not all underlying services. Many institutional customers have redundant services” [emphasis added].


Also, as previously noted that they had “established reciprocal agreements between Rogers and Bell, and between Rogers and TELUS, to exchange alternate carrier SIM cards in support of Business Continuity.”


The implication of this lesson is that we should try to diversify the telecom providers within our professional and personal lives. For example, my personal device is provisioned through Fido (a Rogers sub-brand), while my work cell is provisioned through Bell.  


Lesson #2: Test, Test, Test

They say in real-estate it’s about location, location, location. In change management it’s test, test, test. In the aftermath of the outage, Rogers doesn’t deny that they need to review their change implementation process:

“Most importantly, Rogers is examining its “change, planning and implementation” process to identify improvements to eliminate risk of further service interruptions.”


To be fair, it’s not like there was no testing done. Instead, Rogers had used a phased approach to rolling out the change:

“Concerning the July 8th outage, the proposed activities were very carefully reviewed, as we normally do with all network changes. We validated all aspects of this change.  In fact, we had begun introducing this change weeks ago, on February 8th and had already implemented successfully the first five (5) phases in our core network.” [emphasis added]


It’s a good reminder that in the world of IT General Controls, and IT Risk Management more broadly, it’s not about what goes right but what goes wrong. Consequently, companies should ensure that the scenarios tested are comprehensive enough to identify hidden assumptions or dependencies. For example, Rogers had a procedure that relied on “alternate carrier SIM Cards”. Hypothetically, testing whether this worked ahead of time could help identify whether the employee could find their SIM cards or how they activated such SIM cards when they have no Internet.


Lesson #3: Planning Crisis Communications from Content to Channels

According to the Rogers submission, the company conducted the following communications:

“During the outage, Rogers communicated with customers across several different channels, including social media, media outlets, Rogers Sports & Media properties, website banners, virtual assistants, interactive voice responses (“IVR”), public service announcements and community forums. In addition, Rogers’ CEO conducted broadcast interviews with CP24, Global News, CTV News, BNN, and CityNews. Rogers SVP of Access Networks & Operations also conducted broadcast interviews on CBC and CityNews.”


The following CBC news clip illustrates what was communicated and how:



As can be seen, the reporter was a little surprised that they got message from the IT team – instead of Rogers themselves. However, Rogers did admit that they “will be updating [their] plans and procedures”. Specifically, they plan to:

  • Equip the communications team with “back-up devices on [an] alternate network”
  • Be more timely “in posting details to customer care channels, web properties, social media, as well as public service announcements (“PSAs”) across media properties”
  • Provide more frequent updates “even if there is limited or no additional information to share”
  • Determine an alternative way for the communications team to authenticate themselves, when the second-factor registered with the social media service is reliant on “a device on the Rogers network”
  • Provide specific “status of critical services (such as 9-1-1), how they may be impacted by the outage, and advice for customers”


The outage is a good illustration of how critical crisis communications can be. Maintaining effective communications with customers or other stakeholders is key to minimizing the reputational damage that such incidents can potentially have.


Lesson #4: Monitoring

The final takeaway is the importance of having resources and tools to monitor the restoration efforts. That is, the fixes deployed may not resolve all the issues. Rogers reported the following results with respect to bringing things back online:

“Once the technology team confirmed stability of our core network, and that traffic volumes were returning to normal level across the network, we proceeded to inform customers that our network and systems were returning to fully operational service for the vast majority of our customers. We also notified them that some customers may experience intermittent issues, and that our technology teams are monitoring and would work to resolve any issue as quickly as possible.” [emphasis added]


As can be seen, Rogers was able to restore the service for the vast majority of customers. However, there were a few that still experienced lingering issues. Consequently, it’s important to have continuous monitoring in place to ensure that the service is restored fully before returning to business as usual.

 

Closing thoughts

The incident highlights how dependent society has become on the wireless carriers for the day-to-day transactions and functioning of society. Vass Bednar (also interviewed in the above CBC newsclip) summarized the situation in an op-ed in the Globe and Mail as follows: 


“Enormous advances in mobile tech have made Canada's telecoms enormously powerful, and that power has consolidated in just five major players. That number threatens to get smaller, too, with the proposed Rogers-Shaw merger currently under review by Canada's Competition Bureau. If the deal goes through, the company that caused so many Canadians to lose connection with each other would serve roughly 40 per cent of all households in English Canada… it reinforced the idea that our telecommunication networks are vital public infrastructure that is controlled by private corporations. We've lost sight of that balance, despite the ways we rely on those networks.”


As discussed in the first takeaway, the issue of redundancy is paramount when it comes to ensuring ongoing access. Ironically, the lack of sufficient alternatives in the mobile carrier space amplifies the availability risk for us all.


Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else.

Tuesday, October 4, 2022

Fiona’s Fury: Flashback to Summer’s Great Rogers Outage (Part 1)

Canadians continue to pick up the pieces after tropical storm Fiona battered the maritime provinces. Although estimates of the damage are yet to be calculated, the “Nova Scotia Premier Tim Houston announced over C$40 million ($29.1 million) in support to help those who were impacted by Fiona” (link). In terms of cellphone outages, CBC reported that “there are still areas of the province without cellphone service Monday although companies declined to say exactly  how many customers have been affected.”

 

The Canadian Radio-television and Telecommunications Commission (CRTC) has asked for estimates on how many people were affected by the outage, but the telecom companies are reticent to share this information. As CBC reported: “Bell and Telus asked for some of their submissions to be redacted, while Eastlink and Rogers demanded their entire reports be kept confidential.”


Photo by Pixabay: link

 

Rogers Outage in Review: What happened last summer?

When looking at the outage that hit the Maritimes, it reminds us of the situation that unfolded over the summer. In July 2022, the Rogers outage was not limited to the East Coast. Instead, it affected the entire country. When Rogers was requested to explain what happened, it appears that they had a more conciliatory tone:

“Rogers Communications Canada Inc. (“Rogers”) is in receipt of a letter containing Requests for Information (“RFIs”) from the Canadian Radio-television and Telecommunications Commission (“CRTC” or the “Commission”), dated July 12, 2022, concerning the above-mentioned subject. Attached, please find our Response to that letter… At the outset, Rogers appreciates the opportunity to explain to the Commission, the Government of Canada and all Canadians what transpired on July 8th, 2022.  The network outage experienced by Rogers was simply not acceptable. We failed in our commitment to be Canada’s most reliable network. We know how much our customers rely on our networks and we sincerely apologize.” [Emphasis added]

 

Though the documented was redacted, it did provide some background as to what happened. For this post, we will take a look at the outage itself. For the next post, we will look at the lessons learned.  

 

Cause of the outage

Rogers explained the cause of the outage as follows:

“Given the magnitude of the outage, it appears that Rogers had to be more forthcoming with what happened and were “Maintenance and update windows always take place in the very early morning hours when network traffic is at its quietest. At 4:43AM EDT, a specific coding was introduced in our Distribution Routers which triggered the failure of the Rogers IP core network starting at 4:45AM… The configuration change deleted a routing filter and allowed for all possible routes to the Internet to pass through the routers. As a result, the routers immediately began propagating abnormally high volumes of routes throughout the core network. Certain network routing equipment became flooded, exceeded their capacity levels and were then unable to route traffic, causing the common core network to stop processing traffic. As a result, the Rogers network lost connectivity to the Internet for all incoming and outgoing traffic for both the wireless and wireline networks for our consumer and business customers.” [Emphasis added]

In other words, the change inadvertently resulted in an attack pattern similar to a denial-of-service attack – where the network shutdown because it became overwhelmed with traffic.

They also go on to explain that the company “uses a common core network, essentially one IP network infrastructure, that supports all wireless, wireline and enterprise services. The common core is the brain of the network that receives, processes, transmits and connects all Internet, voice, data and TV traffic for our customers… Certain network routing equipment became flooded, exceeded their memory and processing capacity and were then unable to route and process traffic, causing the common core network to shut down.” The implication being that the common core network became a single point of failure.

 

What was and was not impacted

With respect to Rogers Bank (yes, Rogers operates a bank):

“The impact to the Bank’s customers was minimal as the Bank services were available and the Bank’s customers were able to transact on their Rogers Bank credit cards. There was no interruption in the Bank’s core systems (credit card processing, Interactive Voice Response (“IVR”), Call Centre and customer self-serve mobile application) and these core systems remained available to the Bank’s customers. No critical Bank systems were impacted, and all daily processing was completed as required, including by the Bank’s statement printing vendor and its card personalization bureau which received their daily files and were processing them per standard service level agreements and procedures.”

 

This was a different story for those that relied on Rogers phone lines to process payments at their businesses with Interac tweeting:

“There is a nationwide Rogers outage that encompasses all their business and consumer network services. This is impacting INTERAC Debit and INTERAC eTransfer. INTERAC Debit is currently unavailable online and at checkout..”

 

Beyond the millions who had no service, emergency communications were also impacted:

  • “Unfortunately, the outage of July 8th did impact 9-1-1 service across Rogers’ service area, to both wireline and wireless services.
  • Wireline impact:  There were approximately [REDACTED] 9-1-1 calls placed successfully across Rogers’ network on July 8th.  The typical daily average of total wireline 9-1-1 calls is [REDACTED] per day. Data is unavailable for unsuccessful wireline 9-1-1 calls.  On July 9th, there were approximately [REDACTED] 9-1-1 calls placed successfully across Rogers’ network.
  • Wireless impact: As can be seen in table below, the outage similarly affected wireless 9-1-1. Total successful calls were [REDACTED] the average daily amount of about [REDACTED] 9-1-1 calls made from Rogers wireless devices.”
  •  

Rogers offered service outage credits

The key remedy offered was service credits, but this was not due to breaches in service agreements:

“There was no breach of our service agreements with our retail customers. However, in order to address our customers’ disappointment with the outage, Rogers has already announced it will be crediting 5 days of service fees to its customers. This will be applied automatically to their next invoice.”

 

Cooperation with Bell and Telus

Regardless of the highly-competitive nature of the business, it does appear the Rogers, Bell and Telus were coordinating with each other:

  • “On July 17th, 2015, the Canadian Telecom Resiliency Working Group (“CTRWG”), formerly called Canadian Telecom Emergency Preparedness Association, established reciprocal agreements between Rogers and Bell, and between Rogers and TELUS, to exchange alternate carrier SIM cards in support of Business Continuity.”
  • “As we stated in Rogers(CRTC)11July2022-1.xviii above, our Chief Technology and Information Officer reached out to his counterparts at Bell and TELUS early on July 8th. Assistance was offered by both Bell and TELUS. However, given the nature of the issue, Rogers rapidly assessed and concluded that it was not possible to make the necessary network changes to enable our wireless customers to move to their wireless networks.”
  • “Rogers, Bell and TELUS are presently assessing potential options and will report further findings and potential solutions per the creation of the Memorandum of Understanding that will be delivered in September 2022 to the Minister of ISED by CSTAC.”

In closing, the outage comes down to change management. The error was exacerbated by the industry-standard approach to using a single platform to provide the various telecommunication services. Rogers did offer service credits, but were careful to note that this was not due to breach of agreements. Finally, the industry does come together during crisis situation, putting their competitive differences aside. 


In our next post, we’ll take a look at the lessons learned from this outage. Stay tuned!

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else.

Friday, August 5, 2022

Time to Upgrade the Internet? A look at the hope and hype around Web3

Is the Internet ready for a version upgrade? Some blockchain enthusiasts think so, but others - Tim O'Reilly in particular - think we need to hold off. 

What is Web3?

Deloitte, for its part, sees the Web3 as part of a larger concept of the “semantic web”:

“Many people identify Web 3.0 with the Semantic Web, which centers on the capability of machines to read and interact with content in a manner more akin to humans. Recently, definitions of Web 3.0 have begun to include distributed ledger technologies, such as blockchain, focusing on their ability to authenticate and decentralize information. Theoretically, this could remove the power of platform owners over individual users.”

Gartner links the origins of the term to “Gavin Wood, co-founder of Ethereum, who argues that centralization is not socially tenable long-term. Also called Web 3 and Web 3.0, Web3 eliminates the need for, and functions of, Web 2.0 central authorities and “gatekeepers,” such as major search engines and social media platforms.” [Emphasis from the original quote]

Ethereum, while admitting “it's challenging to provide a rigid definition of what Web3”, lists 4 “core guiding principles, including decentralization, permissionless, use native payments (i.e., cryptocurrencies instead of “outdated infrastructure of banks and payment processors”), and trustless (e.g. relies on miners instead of “trusted third-parties”).

What does Tim O’Reilly, Bill Gates, and Gartner have to say about this?

Tim O’Reilly coined the term “Web 2.0” back in 2005. According to his seminal post on the topic, he introduces the jump from Web 1.0 to Web 2.0 by looking at how Google (which he believes is “the standard bearer for Web 2.0”) compares to Netscape. Specifically, he notes that “the value of the software is proportional to the scale and dynamism of the data it helps to manage.”. He also touches on a number of other concepts, including the ability to harness the wisdom of the crowds, cloud computing, as well as the long tail. 

The original post is worth the read because it gives a benchmark of sorts as to what does “good look like” when claiming the web has gone through a version upgrade.

In terms of what O’Reilly thinks about Web3, it can be found here. He summarizes his primary challenge in a single sentence:

“None of the examples in the article focus on the utility of what is being created, just the possibility that they will make their investors and creators rich.”

The article he is referring to was this one published by NY Time in the fall of 2021. The article mentions, social media, collectibles, and gaming.

Bill Gates is a bit more direct:

“Speaking at a TechCrunch talk on climate change Tuesday, the billionaire Microsoft co-founder described the phenomenon as something that’s “100% based on greater fool theory,” referring to the idea that overvalued assets will go up in price when there are enough investors willing to pay more for them… Gates joked that “expensive digital images of monkeys” would “improve the world immensely,” referring to the much-hyped Bored Ape Yacht Club NFT collection.”

Regardless, O’Reilly and Gates end-up in the same place. Compared to the Railway, Radio, and Internet Bubbles of the past, there is no infrastructure being built here to move people/goods, broadcast programming through the air, or enable the routing of packets of information in a dynamic way that enables us to work from home during a pandemic.

In contrast, there is literally nothing when it comes to crypto. With bitcoin, you do not actually have a tangible thing to hold on to; there are no digital coins or pieces of code to point to. Instead, your holding are mathematical calculation of your “ins” and “outs” (see here for our post/process flow of bitcoin).  Sure, that’s part of the security – but from an economic perspective that is quite a difficult pill to swallow. Add on top of that, there is no centralized intermediaries to turn to when things don’t work out with these “assets” – you have massive issues in understanding how this different than people paying fortunes for tulip bubbles, I mean bulbs.

As noted in the previous post on NFTs, I do think that NFTs offer some type of infrastructure to the future. O’Reilly is not so sure. However, what we do agree is there massive gap on the institutional side of things:

“The failure to think through and build interfaces to existing legal and commercial mechanisms is in stark contrast to previous generations of the web…The easy money to be made speculating on crypto assets seems to have distracted developers and investors from the hard work of building useful real-world services.”

O’Reilly points out that the Web 2.0 – despite the DotCom Crash – still had successful ventures that could be pointed to, such as Amazon and Yahoo that were making money, hiring people, providing services to millions of users and “had all built unique, substantial, and lasting assets in the form of data, infrastructure, and differentiated business model”.

And Gartner?

Gartner on a recent blogpost unveiling its Hype Cycle for Blockchain and Web3, 2002, made an important observation:

“In the meantime, other than cryptocurrency trading, we still have not seen killer use cases yet. They need to leapfrog over current applications in terms of making our lives better.”

Though Web3 is something new, there’s a lot more that needs to be done before it can be crowned a Version 3.0 of the World Wide Web. 


Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else

Tuesday, July 19, 2022

The #CryptoWinter Cometh? Some thoughts to consider

Is crypto winter upon us? It certainly seems that way.

According to Google Trends, fear, uncertainty, and doubt (FUD) around cryptocurrency and crypto-assets is top of mind as we search out the term “crypto winter”: 



Crypto winter, according to the World Economic Forum, is the situation where “prices [of cryptocurrencies and cryptoassets] have dropped a long way and then stayed low for weeks or months”

But is it really just FUD that’s fueling concerns? As noted in the Harvard Business Review:

“The past few months have been dark times for the crypto industry. Between April and June, Bitcoin’s value more than halved, from just over $45,000 to around $20,000; other coins have fallen even more. The Terra-UST ecosystem, which paired a crypto coin with one designed to be pegged to the dollar, collapsed in May, wiping out $60 billion worth of value and leading to cascading failures among crypto lenders. Established companies like Coinbase, a popular crypto exchange, have announced layoffs.”

With respect to Coinbase, they are laying off 18% of their staff (1,100 people) and have explicitly stated that it is due to the coming “crypto winter”:

"We appear to be entering a recession after a 10+ year economic boom. A recession could lead to another crypto winter, and could last for an extended period…"

With respect to the epic Terra-Luna collapse, we should keep in mind that it’s collapse rivals the Bernie Madoff Ponzi-scheme, which was in the $60 billion range as well. For more on what happened, check out Coffeezilla’s take on the matter:

 


Coffeezilla got his start exposing fake gurus, but now is actively exposing crypto-scams. As he notes in the New Yorker:

“Crypto scams are like discovering fentanyl when you’ve been used to Oxy. It’s a hundred times more powerful, and way worse.”

Beyond the Terra-Luna collapse, he has a great video on Celsius, a crypto-lender that offered exorbitant interest rates on deposits:


Celsius attempted to ride the anti-bank sentiment claiming that it wasn’t a bank, but they took deposits and then lent out loans on interest – which is exactly what a bank does.

Now they are no more: they have filed for Chapter 11 bankruptcy. In an added twist, they are claiming that the people who deposited funds with them are not account holders. Adam Levitin, a Georgetown law professor, explained to CNBC that:

“The treatment here seems to be that the customer’s crypto is actually the company’s property, and as an unsecured creditor, you don’t get your bitcoins back”

What does this all have to do with the crypto-winter?

These crypto-collapses have had a material impact on the industry. Reuters linked the 14% price drop in mid-June 2022 to Celsius freezing “withdrawals and transfers”.

With such spectacular disasters, what is in store for world of crypto and the promise of Web3? That's the topic we will explore in our next post!

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else



Thursday, May 5, 2022

NFTs: Heading for the Trough of Disillusionment?

The recent sale of NFTs from Yuga Labs showed both the promise and the peril of the hyped technology. On the one hand, Yuga Labs made “$320 million in what was considered the “largest NFT mint in history”, with its “sale of Otherdeed nonfungible tokens that represent digital land deeds on their new venture, the Otherside metaverse”.

 

Minting is the NFT equivalent of an “initial public offering” (IPO). But instead of selling stock, they are selling a digital token. In this case it was land rights in “a metaverse game world”. Each parcel of “digital land” was sold for “305 ApeCoin (APE), or nearly $5,800”. The incentive for the buyer is to get in early and then sell the NFT on secondary markets. For example, on OpenSea (a major reseller of NFTs) the Otherdeeds were selling for an average of just over 9 ether (ETH) or nearly $27,000.  

 

The peril?

 

The rush to cash in on this craze resulted in overloading the Ethereum blockchain. And that didn’t just result in slow service. It cost millions: $123 million. Users got hit with transaction costs that exceeded the cost of the “digital land deed”, coming in between “2.6 ETH ($6,500) to 5 ETH ($14,000)”.

 

In contrast, Visa charges merchants between “2.87 percent and 4.35 percent per transaction”, which would have been about $160-$260 per sale. It’s hard to see how the decentralized finance (DeFi) approach is superior to the “classic” approach of centralized finance (CeFi).

 

So, should we discard NFTs?

 

NFTs: What took them to the Peak of Inflated Expectations?

Before running for the hills and closing the books on NFTs, we should remember the Dotcom era. It was the late 1990s, Google was still a scrappy start-up and Microsoft was seen as the bully those days. And people will all starry eyed about the “new Internet economy’. Slap a “.com” behind your company’s name and voila! Millions of dollars of investment would be thrown at you.

 

So, is history repeating itself? In a sense, yes.

 

According to Gartner’s Hype Cycle, there is an initial hype phase when the innovation causes mania in the markets, which is known as the “Peak of Inflated Expectations”. That is, the innovation is seen as that silver bullet that will cure all.

 

Conceptually, NFTs provide a means to create “digital scarcity”, hence the term “non-fungible”. Specifically:

“NFTs allow ownership and use rights to be demonstrated for any piece of digital content by assigning the content a specific, nonduplicable identifier that is recorded on a distributed database, or blockchain, typically Flow or Ethereum.” (link)

 

This then allows physical collectible items – basketball cards, comic books, art, and so on – to be unique digital items. Previously, this was not possible as all digital “assets” were fungible, i.e. copies of copies with no way to distinguish one from another.

 

A secondary area of value within NFTs is the use of algorithms to generate art.  Specifically, algorithms are used to synthesize “different design features, accessories, and special traits… [to create] thousands of unique combinations.” In other words, an artist does not have to generate each work of art. Instead, they can “draw” one piece and then let the algorithm generate thousands of images based on that initial design. For example, the “Ape images” generated as part of the Bored Ape Yacht Club “collection” relied on this “procedural algorithms that can create tiers of rarity and value”.

 

Beyond art, sports media looks to be a potentially lucrative NFT market. Deloitte Global predicts between 4 to 5 million gifts/purchases for such digital work that “will generate more than US$2 billion in transactions in 2022”.   

 

Entering the Trough of Disillusionment: 10 Challenges with NFTs

The value of NFTs is intuitive at first glance. But there are challenges. The emergence of these problems, issues, and outright scams is a sign that we are heading into the next phase of Gartner’s Hype Cycle which is “the Trough of Disillusionment”. If this was the early days of the Internet, it would be the moment when investors realized that pets.com was not such a good idea after all. It’s in this phase that the problems with the innovation become apparent. Let’s look at 10 issues that have arisen with NFTs.

 

Issue #1: Blockchain does not scale like the Cloud

The +$100 million gas bill that Ethereum effectively issued to “digital land deed” speculators was not a first. This problem was previously experienced with CryptoKitties. As noted in this paper, “CryptoKitties was the first widely recognized blockchain game. Players could own, breed, and trade kitties, which are the only prop in the game.” The paper explains how collectors experienced massive gas bills from Ethereum to get in on the hype:

“The cost of performing operations on a public blockchain system is highly volatile due to the unstable price of cryptocurrencies, resulting in it difficult to control the cost of the applications deployed on the blockchain. As CryptoKitties was deployed on Ethereum, the cost of playing the game (including the costs of buying, breeding, and renting kitties, as well as the fees paid to Ethereum miners) has risen significantly due to the rapid rise of Ether price in the third stage. Ether price increased from US $451 on December 10, 2017, to US $1,322 on January 10, 2018…resulting in a significant increase in the cost of playing the game, raising the bars for new players entering the game.” [Emphasis added]

 

We’ve been conditioned by the cloud to expect automatic scaling; such bottlenecks seem to harken back to a more primitive era of computing. However, that’s the price of trust. The proof-of-work consensus mechanism is designed precisely to slow things down to allow for the miners to verify the transactions and prevent hackers from committing non-authorized records to the blockchain.

 

Issue #2: NFTs do not necessarily convey digital ownership

According to Deloitte Global: “Ownership of an NFT may include ownership of the underlying digital asset, though most sports NFTs sold to date have no ownership or use rights in the underlying media.” [Emphasis added, italics from original]

 

But perhaps a bigger smoking gun is at Christie’s auction house – the same one that sold Beeple’s digital artwork for $69 million. As highlighted by the well-known nocoiner, David Gerard: “Christie’s auction of an NFT is a fabulous worked example. There’s a 33-page terms and conditions document, and if you wade through the circuitous verbiage, it finally admits that … you’re just buying the crypto-token itself…”

 

He goes on to cite the terms of sale, right from the Christie’s site, which clearly states:

“You acknowledge that ownership of an NFT carries no rights, express or implied, other than property rights for the lot (specifically, digital artwork tokenized by the NFT)…”

 

Issue #3: If all that’s transferred is a hash, then where’s my “digital asset”?

The “what” is not the only issue. The ”where” is also an issue. As noted on CoinDesk: “On the simplest level, an NFT is a record (a document with a hash) stored on Ethereum (usually) that points to where its associated content (the image) lives somewhere else on the internet (it's much too expensive to store images on Ethereum).” [Emphasis added]

 

Like scalability, we are accustomed to the idea that storage is cheap and plentiful. But such assumptions don’t hold for the blockchain. Therefore, this disconnect between the location of the ownership record and the digital item itself can be baffling. Moreover, this approach contradicts that generally accepted wisdom that ‘possession is nine-tenths of the law’.

 

Issue #4: Is digital art a great vehicle for money laundering?

As noted by the US Department of the Treasury: “…the emerging digital art market, such as the use of non-fungible tokens (NFTs), may present new risks, depending on the structure and market incentives.”

 

Though specifics were not provided, it’s not surprising the that the US government has their eye on the area. Given the reputation that Bitcoin has for us in less than legal transactions, it’s not surprising that NFTs potential for nefarious purposes.

 

 

Issue #5: NFT Price Volatility is an Understatement

One of the more famous NFTs was Jack Dorsey’s first tweet, which was sold for $2.9 million. According to the Guardian, Sina Estavi, a crypto entrepreneur, who bought the tweet wanted a cool $48 million for it. What was he offered? According to CBS, only $280.

 

Issue #6: You could be buying an NFT that has been copied without the author’s permission

OpenSea noted in a tweet that “Over 80% of the items created with this tool were plagiarized works, fake collections, and spam.” Perhaps, the worst incident of this was how fraudsters sold the work of a dead artist. Moreover, “NFTs themselves can be used to fraudulently attribute digital designs to multiple owners”.

 

Issue #7: The superstar NFT artists make all the money, the rest of us don’t

The hype would make us believe that we all can get rich from NFTs. A study published on Nature found that 75% of NFTs sold for a price less than $15:

“We observe that the average sale price of NFTs is lower than 15 dollars for 75% of the assets, and larger than 1594 dollars, for 1% of the assets. Considering individual categories, NFTs categorized as Art, Metaverse, and Utility reached higher prices compared to other categories, with the top 1% of assets having average sale price higher than 6290, 9485, and 12,756 dollars respectively.”

 

Issue #8: For all the promise of blockchain’s transparency, opaqueness abounds

As noted earlier, digital artist Beeple (Mike Winkelmann) sold his "Everydays - The First 5000 Days" for $69 million. But the buyer was a mystery. But nocoiner Amy Castor had a hunch. She thought it was MetaKovan (Vignesh Sundaresan). And this was confirmed on CNBC.

 

But so what? It turns out that MetaKovan and Beeple were already business partners.

 

Beeple owns 2% of the B20 tokens that is behind Metapurse “a crypto-based investment firm”. Metapurse is controlled by MetaKovan. That firm had previously purchased “Beeple’s “Everydays: 20 Collection” artworks for $2.2 million”. (See Castor’s post here). Though the "Everydays - The First 5000 Days” is owned by MetaKovan and not Metapurse, the previous relationship does dampen the hype behind the sale and calls to us to question the valuation.

 

But a more important question, is why wasn’t this visible on the Ethereum blockchain? According to Castor:“…it sounds like the funds may even have gone into Christie’s escrow wallet…Anyhow, if both parties had Coinbase accounts, the exchange could just change the database records off-chain to flip account balances. In this way, Coinbase acts like a second layer, and you wouldn’t see the ETH transaction.” [Emphasis added]

 

Issue 9: NFTs still rely on “classic” intermediaries for mega sales

NFTs that sell the best still rely on “old-world” forms of intermediaries. That is, NFTs are not a way for the “common person” to make it rich simply because of their artistic talent. Instead, the more successful NFTs rely on the following:

·        Celebrity endorsements: Paris Hilton, Jimmy Fallon, Eminem, and others used their celebrity status to give a boost to the NFT “Ape Art” from the Bored Ape Yacht Club.

·        Whitelisting: Bloomberg reported on Chainanalysis’s finding that “[t]he practice of whitelisting appears to be similar to the preferential treatment of some insiders and investors that has long been practiced in the cryptocurrency world, especially with so-called initial coin offerings before the sales were shut down by regulators”. Citing the Chainanalysis study, Bloomberg also noted that “[u]sers who make the whitelist and later sell their newly-minted NFT gain a profit 75.7% of the time, versus just 20.8% for users who do so without being whitelisted”

·        Official Auction Houses: Beeple did not sell his $69 million piece of digital art on some random site on the Internet. He sold it at Christie’s. Christie’s has been around since 1766. It doesn’t get more classic than that.

 

Issue 10: NFTs are rife with information security issues

Speaking as a CPA/CISA, one of the craziest aspects of NFTs is that the process requires you to grant the entity issuing NFT (or the minter) logical access to your wallet. And what happens if you grant access to the wrong individual, i.e. a hacker? All that crypto will be emptied out.

 

The other scam that is out there is that people can “airdrop” an NFT into your wallet. And if you click on that? As RAC explained to Rolling Stone, “[e]verything’s programable, so what they do is they make these tokens unsellable. It basically locks you into something and forces you to give them access to your funds, and then they steal your money.”

 

What RAC is referring to is the programmability that’s baked into the Ethereum blockchain. Consequently, clicking something (even deleting something) could initiate malware that would result in your digital wallet being drained of funds.

 

Closing thoughts:

 

So with all these problems, what does the future look like?

 

It’s really about governance. The unregulated nature of stocks in the 1920s ultimately led to the Great Depression, which brought the Security Exchange Commission into existence and the need for financial audits. Similarly, governance will ultimately need to be implemented to enable true ownership of not just the hash in the NFT but the underlying asset. That is, just like you own a painting, you should have the underlying code that is the actual digital art.

 

In terms of AML, Know Your Customer (KYC) controls are percolating at NFT marketplaces. Wired reported that:

 

“A Twinci spokesperson says the platform is implementing something like this at the moment – it is verifying artists to make them stand out from ordinary users. Green-ticked artists have verified their identity in a process similar to how Twitter doles out its blue ticks. People are asked to give their name, a photo of themselves, proof of them creating an artwork as well as a digital portfolio. Twinci cautions its community to re-consider collecting NFTs from non-verified artists.”

 

But doesn’t this contradict the decentralization that blockchain is supposed to bring?

 

The challenge with this idea is largely based on the myth of individualism. Society is not simply composed of individuals. Rather, it’s the institutions and collectively shared norms that hold society together. For example, if Canadians did not collectively respect private property then anything you held could be stolen without recourse. But perhaps the greatest illustration of such conventions goes back to how disputes were handled on the blockchain itself. Consider the DAO hack of 2016. The consensus amongst the Ethereum community felt and injustice was done because of the theft of ether (the cryptocurrency used on Ethereum). So they turned to Ethereum’s leader/inventor, Vitalik Buterin, to mutate the immutable. This is why the term “immutable” shouldn’t really be used; tamper-resistant is more accurate.

 

Consequently, once such myths give way to practical necessities of governance (e.g. SEC-type organizations managing minting, courts opining on digital ownership, ISO standards, etc.); we will be on our way from the current wild west to something safe and stable. Again, this is history repeating itself. The cloud took time for standards to take hold. For example, cloud service providers see the SOC2 audit report on the IT controls as a standard. But it wasn’t always. In the early days of cloud, it was rumored that Eli Lily had to walk away from Amazon because they could not offer the IT controls that they needed (which Amazon denied). Regardless, the security norms took a while to become the status quo. Similarly, this standardization is part of the process to take the NFTs from the Trough of Disillusionment to the Slope of Enlightenment. This is the next phase of Gartner’s Hype Cycle. Only time will tell how players within the industry will coalesce around such standards given that the NFT/blockchain evangelists are still stuck with the idea that society is unnecessary.


Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else